Account and access
Invite and manage users
Invite people with intentional access, review invitation status, update memberships, and deactivate organization access safely.
Updated August 8, 2026
Overview
Invite people to join your organization, then manage each person’s roles and department access. The person’s FTE Tree account remains their own; organization administrators manage only their access to that organization.
Give every person an individual account so approvals, comments, imports, and activity remain attributable.
Access needed
You need Manage user access. You can grant only permissions and departments that you are authorized to grant. Invitation and access changes require a recent MFA check.
Before inviting someone
Confirm:
- The person’s exact email address.
- The person’s name and optional Job title as they should appear in this organization.
- Whether the organization’s email policy allows that domain.
- The roles needed for the person’s responsibilities.
- All departments or the specific departments the person needs.
- Whether company sign-in is required.
- Whether the invitation should start immediately or on a scheduled date.
A blank department selection grants no department access. It never means all departments.
Send an invitation
- Open the invitation list.
- Select Invite user.
- Enter the person’s name, optional Job title, and email address.
- Choose one or more access roles.
- Choose department access when the role requires it.
- Set availability dates when needed.
- Review the summary.
- Submit and complete MFA if prompted.
Choose Invite without access roles only when the person should join before responsibilities are known. After acceptance, areas that require an access role remain unavailable until someone who can manage user access assigns one.
Review invitation status
An invitation can be:
- Scheduled.
- Active.
- Expired.
- Cancelled.
- Accepted.
- Blocked by a changed role or policy.
Use Send reminder for an active invitation. Update the invitation when its roles or dates should change. Cancel it when it should no longer be accepted; cancellation preserves history.
If the address is wrong, cancel the invitation and send a new one. The recipient must accept with the same verified email.
What happens on acceptance
The Job title, selected roles, and departments become part of the membership when the recipient accepts, so their first organization visit has the intended identity and access. A Job title helps distinguish people in user and approval lists; it does not grant access.
Acceptance is blocked when a selected role is no longer available or the verified email no longer meets the current policy. Update the invitation rather than asking the recipient to work around the check.
If company sign-in is required, invitation acceptance does not bypass it.
Manage an existing user
Open the user list and select the membership to:
- Review the roles and departments that currently provide access.
- Add or remove role assignments.
- Review membership activity and history.
- Update the optional Job title shown with the person’s name in this organization.
- Update organization notification settings where applicable.
- Deactivate organization access.
Access changes take effect when the person next opens a page or takes an action.
Deactivate organization access
Use Deactivate user access when the person should no longer enter this organization.
Deactivation:
- Ends the active membership and role assignments.
- Keeps approvals, comments, messages, imports, and activity in history.
- Does not deactivate the person’s FTE Tree account.
- Does not affect other organizations.
- Allows the person to be invited again later.
You cannot deactivate your own organization access from this page, and FTE Tree protects the administrative access needed to keep an organization manageable.
Do not rename or reuse an old account for a new person.
Review user access
Run the Access review report:
- After inviting a group of users.
- After changing the department hierarchy.
- After changing compensation, security, billing, or company-group access.
- Before a formal access review.
The report keeps name, Job title, and email in separate columns so reviewers can identify people without treating the title as an access role.
A No department access entry grants no department access. Correct it by selecting specific departments or All departments.
Common questions
Why can the invited user join but see no records?
The invitation may have no role or no department access. Review the person’s current access.
Why can I not grant a role?
The role may be unavailable, or it may include permissions or departments you are not allowed to grant.
Does deactivation delete the user’s activity?
No. Business history stays connected to the person.